Live data from Hacker News

Sinkholed

susam.in

81–90 of 135 posts

Re: Sinkholed

#81
A couple of years ago we lost our domain [1] due to a registrar (that we were not a customer of) erroneously issuing a suspension. The amount of honor system involved in the whole process, particularly in ccTLDs without as much oversight, was really surprising.

[1]: https://medium.com/thisiscala/the-duct-tape-holding-the-inte...

Re: Sinkholed

#82
post #9

Earlier quoted context omitted.

The FBI and analogous TLAs do this all the time. And generally, there's no recourse. In many cases, sites have resorted to distributing their IP addresses.

Personally I’d rather deal with the FBI accidentally seizing a domain than some foreign entity.

You'd be in luck, the Shadowserver Foundation is essentially a proxy for the FBI.

They control various seized assets seemingly unrelated to their publicly stated mission, like libertyreserve.com. Shadowserver used to host the seizure page for liberty reserve too.

Re: Sinkholed

#83

Earlier quoted context omitted.

> Shadowserver Foundation

The Foundation didn't seize the domain, it just suggested to the NIXI that they should do so.

“Why did you seize our domain?”

“Shadowserver said it was bad”

“But it’s not bad”

“Take it up with them. I hope you speak German.”

Re: Sinkholed

#84
post #25
post #14

Earlier quoted context omitted.

Thank you for this comment. I have not consulted a lawyer. I have not suffered any monetary loss due to this yet. I use this domain name only to run a small personal blog (the one linked to in this post) and an Exim4 MTA. The fact that the MTA became unreachable via the domain name did mean that some emails sent to it must have bounced back. The primary loss I suffered was in terms of time. In fact, I appreciate the…

Yes, I get that the Shadowserver Foundation does good work. And that they acted quickly, after being pointed to your tweet. However, if your tweet hadn't gotten traction, and if Namecheap hadn't been proactive, you'd likely have never gotten the domain back. I mean, you had the Namecheap CEO on the case! And for a business losing a domain like that, it'd probably be fatal. I get that many think that Americans are hug…

> I get that many think that Americans are hugely too litigious. But there is the argument that there ought to be compensation for damages.

That point of view is rather unfortunate. Why does it have to be about damages? GP even ends his comment on a very postitive note about things that would help. Not every mistake needs to be punished. It was a false positive, and it was heartening to see that all the parties acted fast enough. Why not just move on instead of outraging over hypothetical concerns?

EDIT: I have no idea how to quote parent comments here.

Re: Sinkholed

#85

Earlier quoted context omitted.

I don't see any mention of a court; the TLD manager (NIXI) probably took the initiative based on said erroneous information.

NIXI is subject to the jusrisdiction of CERT-IN (Indian Computer Emergency Response Team - https://cert-in.org.in/ ), which in turn was one of the participants of the Avalanche takedown program. A legal request originating from Germany would have been approved by CERT-IN and NIXI would have had to comply. https://www.cyberswachhtakendra.gov.in/alerts/avalanche.html

AFAICT, CERT-Bund (the German CERT) believes what Shadowserver tells them. When CERT-Bund makes a request onward ,it looks more official, but I don't believe any more actual vetting happens.

Re: Sinkholed

#86
This kind of thing makes picking a personal email address a tricky decision.

Do I go with a @gmail.com or other corporate address? Then I risk losing my email if my account is suspended.

Do I go with a domain I own? Then I risk losing it if something like this happens.

Either way is serious because email is effectively a master key into all my accounts.

I'm honestly not sure what's best.

Re: Sinkholed

#88

A couple of years ago we lost our domain [1] due to a registrar (that we were not a customer of) erroneously issuing a suspension. The amount of honor system involved in the whole process, particularly in ccTLDs without as much oversight, was really surprising. [1]: https://medium.com/thisiscala/the-duct-tape-holding-the-inte...

That's worth resubmitting to HN.

Re: Sinkholed

#89

> My website was missing. In fact, the domain name resolved to an IPv4 address I was unfamiliar with. Do you guys know this stuff? If my domain started resolving to a new IP address, that would be just as unfamiliar to me, as the current address. Should I ping my domain and write the results down?

If you have a small infrastructure, knowing your IPs is useful.

For a larger one, the netblock(s), ASNs, or hosting. provider / region.

Re: Sinkholed

#90

Earlier quoted context omitted.

This is something that can absolutely be decentralized. Problems aside namecoin shows that it can be done. The entire domain name system needs to be overhauled, central certificate authorities need to be avoided. The internet in general is infrastructure, and protocols that are increasingly controlled by governments and organizations in bed with governments.

That also has its downsides though. For starters, it would no longer be possible to take down domains used for controlling botnets.

Intelligent botnet authors will switch to the decentralized options once they are widely available and stable. While I think there's limited benefit to decentralization for any use case I care about, I don't think centralization is going to stop this trend in the medium term.
Post reply on HN